QuantForge AI v0.1.0
QuantForge AI v0.1.0 is the first public release of the governed, deterministic, offline Phase 1
research-tribunal foundation. It is designed to test whether quantitative evidence deserves trust;
it is not a trading system.
Included foundation
- an Experiment Constitution with human approval and amendment lineage;
- an evidence ledger and typed acyclic claim graph binding claims to source evidence;
- a tamper-evident, hash-chained audit record with complete single-case semantic replay;
- a deterministic, code-owned verdict policy whose result cannot be upgraded by advisory roles;
- offline typed mock roles and byte-stable synthetic fixtures for provisional, fragile, and
inconclusive outcomes; - strict schemas, canonical JSON identity, explicit workflow authority, and conservative state
transitions; - the independent Phase 1 audit and repaired High/Medium findings with regression protection.
Validation and reproducibility
The exact tagged source candidate passed cross-platform CI on Ubuntu, macOS, and Windows with
Python 3.12–3.14, plus CodeQL, secret scanning, malicious-input regressions, runtime and development
dependency audits, and immutable GitHub Action pin validation. Two isolated wheel/sdist builds were
byte-identical. The release includes package inspection evidence, an installed-wheel smoke result,
deterministic scenario evidence, SHA-256 checksums, and a CycloneDX 1.6 SBOM that binds the package
to the tagged source commit.
The wheel installs and runs outside the source tree. quantforge --version, all offline demos, case
validation, audit-chain verification, semantic replay, and deterministic file hashes were verified
without an API key, live provider, market-data feed, broker, or network service at runtime.
Deliberate limitations
This release is not production-ready and does not include real OpenAI execution, live model
providers, C++ engine integration, market-data ingestion, retrieval, persistence, a web UI, broker
connectivity, order submission, live trading, autonomous investment authority, production
deployment, investment advice, or a profitability claim. Its audit nonrepudiation is local rather
than externally signed or anchored.
See the repository's validated v0.1.0 release notes, release policy, security model, and independent
audit evidence for the complete scope and verification record.